FIN7__2022__FIN7_TLPCLEAR.pdf
ID: a6ad7820-3cca-4f8a-bca7-677f675eba05
STIX ID: report--a6ad7820-3cca-4f8a-bca7-677f675eba05
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2022-12-22
Last Modified Date: 2022-12-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive summary:** This PRODAFT report provides a comprehensive investigation of the FIN7 cybercrime/APT group, exposing its hierarchical organization, tailored tooling (Tirion/Lizar, custom PowerShell droppers, loaders), large-scale automated attack platform for Microsoft Exchange (ProxyShell/ProxyLogon) and SQLi, social-engineering (BadUSB, spear-phishing) methods, ransomware affiliations (REvil, DarkSide, LockBit), victim prioritization processes, post-exploitation toolset (SSH backdoors, Cobalt Strike, rclone exfiltration), and a lengthy set of IOCs and hashes useful for detection and response.
